CVE-2026-9917: Uninitialized Use in WebGL in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to...
Uninitialized Use in WebGL in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)
This is a Chrome for Android memory disclosure issue in WebGL. A victim who opens a crafted web page could expose potentially sensitive process memory. The CVE rates it medium with high confidentiality impact, and the sources do not show confirmed active exploitation.
Executive priority
Treat this as a timely mobile browser update issue, not a crisis. Confidentiality impact is high, but exploitation requires user interaction and no active exploitation is cited. Prioritize Android Chrome patch compliance within normal expedited browser update processes.
Technical view
CVE-2026-9917 is a CWE-457 uninitialized-use flaw in WebGL affecting Google Chrome on Android prior to 148.0.7778.216. CVSS 3.1 is 6.5: network attack vector, low complexity, no privileges, user interaction required, high confidentiality impact, no integrity or availability impact.
Likely exposure
Organizations are exposed where Android devices run Chrome versions earlier than 148.0.7778.216, especially unmanaged BYOD or delayed mobile update channels. The bundle does not identify other affected Google products or platforms.
Exploitation context
The CVE says a remote attacker could use a crafted HTML page to obtain potentially sensitive information from process memory. KEV is false, and the supplied sources do not provide evidence of exploitation in the wild.
Researcher notes
The record is specific to WebGL uninitialized memory use and information disclosure. Do not assume code execution, sandbox escape, or non-Android impact from the supplied evidence. The Chrome Releases desktop reference may not fully document Android-specific remediation details.
Mitigation direction
Update Chrome on Android to 148.0.7778.216 or later.
Based on public source material and reviewed before publication.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cwe · low confidence lookup
CWE-457: Exact CWE lookup
Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve
time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present,
the table keeps the source vectors side by side instead of collapsing them into the highest score.
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
CWE-457 · source CWE mapping
Use of Uninitialized Variable
Use of Uninitialized Variable represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.